Team viewing data breach warning on multiple laptops

October 19, 2025 - Daily Cybersecurity News

Malicious Google Ads Distribute Infostealers via Fake Homebrew and LogMeIn Sites

High

What happened

Threat actors are leveraging malicious Google advertisements to direct users to counterfeit websites mimicking Homebrew, LogMeIn, and TradingView. These sites prompt users to execute commands in the Terminal, leading to the installation of infostealing malware such as AMOS (Atomic macOS Stealer) and Odyssey.

Who is affected

macOS developers and users seeking to download or update software from Homebrew, LogMeIn, and TradingView platforms are the primary targets of this campaign.

Why it matters

The distribution of infostealing malware through trusted platforms poses significant risks, including unauthorized access to sensitive information, credential theft, and potential financial losses. The use of legitimate-looking advertisements increases the likelihood of successful infections.

How it could have been prevented

- Always verify the authenticity of websites by checking the URL and ensuring it matches the official domain.- Avoid clicking on sponsored ads for software downloads; instead, navigate directly to the official website.- Regularly update and maintain robust endpoint protection solutions to detect and prevent malware infections.

Relevant professional terms

Infostealer
A type of malware designed to gather sensitive information from a victim's system, such as login credentials, financial data, and personal information.
Malvertising
The use of online advertising to spread malware, often by embedding malicious code within legitimate-looking ads.

Recommended reading: Fake Homebrew Google ads target Mac users with malware

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

High

What happened

A previously undocumented .NET malware, dubbed CAPI Backdoor, has been identified targeting Russian automobile and e-commerce sectors. The attack involves phishing emails containing a ZIP archive, which includes a decoy document and a Windows shortcut (LNK) file that executes the malware.

Who is affected

Organizations within the Russian automobile and e-commerce industries are the primary targets of this campaign.

Why it matters

The CAPI Backdoor enables attackers to steal sensitive data from web browsers, capture screenshots, collect system information, and maintain persistent access to compromised systems, posing significant security risks to affected organizations.

How it could have been prevented

Implementing robust email filtering to detect and block phishing attempts, educating employees on recognizing phishing emails, and maintaining up-to-date antivirus software can help prevent such infections.

Relevant professional terms

Living-off-the-land (LotL) technique
Utilizing legitimate system tools and processes to conduct malicious activities, thereby evading detection.
Persistence
Methods employed by malware to maintain access to a compromised system across reboots and other interruptions.

Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT

High

What happened

The cybercrime group Silver Fox has expanded its operations, deploying the Winos 4.0 malware and HoldingHands RAT to target organizations in Japan and Malaysia through phishing emails containing malicious PDFs.

Who is affected

Organizations in Japan and Malaysia are the primary targets of these attacks.

Why it matters

The expansion of Silver Fox's activities to new regions indicates a growing threat landscape, emphasizing the need for heightened vigilance against sophisticated phishing campaigns and malware deployments.

How it could have been prevented

Implementing comprehensive email filtering to detect and block phishing attempts, and conducting regular employee training on recognizing and reporting suspicious emails.

Relevant professional terms

Phishing
A cyber attack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Remote Access Trojan (RAT)
A type of malware that allows unauthorized remote control over an infected computer.

Recommended reading: HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks